Privacy Policy

Effective August 3, 2026 · Version 2.2

Plain-language summary: customers decide what business and employee data to place in SR&ED Copilot. We process it to provide the service, use disclosed providers, do not sell it, and do not use it to train our own AI models. Processing is not guaranteed to stay in Canada. Keep authoritative records elsewhere and upload only what your organization approves.

1. Who is responsible

Andrew Marc, carrying on business as SR&ED Copilot operates SR&ED Copilot (the “Service”) and is responsible for the account, website, billing, support, and security information it uses for its own service operations. Contact details appear below.

For project, evidence, integration, employee, and expenditure data, the customer organization decides what to collect and why. The customer remains accountable for that information and SR&ED Copilot processes it on the customer's instructions. See our Data Processing Addendum.

2. Information we collect

Account and organization data

  • Name, business email address, organization name, role, and login credentials in hashed form
  • Invitations, account preferences, assessment responses, and subscription status
  • Support requests, feedback, legal and procurement communications

Customer-directed SR&ED data

  • Claimant legal name, business number, and, if an individual claimant chooses to provide it, social insurance number
  • Project names, descriptions, fiscal periods, hypotheses, uncertainties, experiments, results, and advancements
  • Manual evidence and authorized integration data such as commit text and metadata, tickets, work items, and selected Slack or Teams messages
  • Names, email addresses, display names, authorship, timestamps, message links, tags, and project attribution
  • Personnel, contractor, material, overhead, amount, and time-period information used in expenditure preparation
  • AI prompts, selected evidence, generated narratives, citations, edits, reviews, preparation results, and exported package metadata

This scope can reveal trade secrets, product architecture, security details, financial information, tax identifiers, and employee information. Avoid entering a social insurance number unless it is necessary for the selected workflow and your privacy process approves it. The Service is not intended to receive passwords, access keys, payment-card data, personal health information, or unrelated customer data.

Integration data

  • Connected service, authorized scopes, external account or workspace identifiers, and synchronization metadata
  • OAuth access and refresh tokens, stored with application-level authenticated encryption
  • Records the customer chooses or configures the Service to import

Usage, security, and website data

  • IP address, request and event times, browser and device information, page URL, and error or security logs
  • First-party operational request logs and security events needed to run and protect the Service
  • Selected first-party, content-free product events, such as opening an educational guide or starting a government-assistance entry, with the interface source that led to the action
  • On designated public marketing and registration pages, Google Ads receives page and device metadata, consent signals, permitted ad-click identifiers, and a completed-sign-up event for campaign attribution. Form fields, account email addresses, and customer SR&ED content are not included in that event.
  • Third-party browser measurement remains disabled on authenticated product, welcome, invitation, and password-reset routes.
  • Selected audit records for changes, generation, review, organization administration, and exports

Billing data

Stripe may collect billing contact, card, tax, and transaction information during checkout. SR&ED Copilot receives transaction and subscription metadata but does not intentionally store full payment-card numbers.

3. How we use information

  • authenticate users, enforce organization and role boundaries, and secure the Service;
  • collect and organize evidence, identify documentation gaps, support review, and produce exports;
  • send customer-selected evidence to the selected AI provider and store returned drafts;
  • operate integrations according to customer-authorized scopes and configuration;
  • administer subscriptions, transactional email, support, and legal requests;
  • diagnose defects, prevent abuse, investigate incidents, and maintain audit records; and
  • understand product use and measure website campaigns.

We do not sell personal information or customer content. We do not use customer content to train an SR&ED Copilot model.

4. AI processing and automated output

When a user starts a generation or improvement request, the prompt and selected evidence text are sent to Cohere, Anthropic, or OpenAI according to the selected model and credential mode. Supplying your own API key changes whose credential is used; it does not keep the content out of that provider's systems. Customer-supplied keys are used for the request and are not intentionally persisted by SR&ED Copilot.

Organization owners can disable AI processing, require customer-supplied keys, or restrict the provider allowlist. The enforced data-minimization policy limits generation context to project name, description, fiscal year, and technology stack; selected evidence IDs, sources, titles, summaries, dates, tags, and links; instructions; and draft narrative text when improving a draft. Raw integration payloads are excluded from that context.

We rely on applicable provider API or commercial terms for restrictions on model training. AI drafts can be inaccurate and are not eligibility decisions, tax advice, or filing decisions. A person must review the facts, source citations, calculations, and final filing package.

5. Who receives information

Information may be disclosed to:

  • other authorized users in the customer's organization according to their role;
  • hosting, AI, email, billing, and other providers listed in our Subprocessor Register;
  • customer-directed integration services when the customer connects or synchronizes them;
  • professional advisers bound by confidentiality where reasonably necessary;
  • authorities or other parties when required by a valid legal demand or necessary to protect rights and safety; and
  • a proposed successor in a business transaction, subject to Section 10.

6. Cross-border processing

Core production hosting is currently in the United States on Render. Service data may also be processed in Canada, the United States, or other locations used by a disclosed feature provider. The self-service Service does not offer Canadian-only storage or processing. Information in another country may be accessible under that country's laws.

If your employer, customer contracts, regulator, or data-classification policy requires Canadian residency, do not upload the data unless a written arrangement satisfying that requirement is in place.

7. Security

Current controls and known gaps are described in Security & Data Handling. Important limitations include the lack of independent security certification and the lack of field-level encryption for all evidence, narratives, and expenditure fields. OAuth tokens and claim filing workspaces do use application-level authenticated encryption. No security measure eliminates all risk.

8. Retention and CRA records

Retention depends on record type, account status, configured organization settings, legal requirements, and provider backup rotation. New workspaces default to an 84-month conservative planning window; existing organization settings remain explicit and can be changed by an owner. The setting currently flags older evidence and does not silently delete it. It is not a representation that the Service satisfies CRA's recordkeeping rules or your organization's schedule.

  • Customer content: generally retained while the account is active, subject to product delete actions and verified deletion requests. The current planning-window check is status-only.
  • Generated drafts: retained until deleted, the associated data is deleted, or the account is offboarded, subject to backups and legal exceptions.
  • Audit records: retained for accountability and security subject to verified deletion, legal, backup, and operational requirements; no automatic age-based purge is currently claimed.
  • Expired session records: expiry and revocation prevent authentication. No recurring database cleanup schedule is currently represented; residual session records remain access-controlled until verified maintenance or deletion.
  • Billing and legal records: retained as reasonably required for tax, dispute, fraud-prevention, and legal obligations.
  • Backups: deleted data may remain until managed-provider backups rotate; we do not promise immediate item-level backup deletion.
CRA generally requires relevant books and records to be kept for years. Keep the source records in an approved repository, export project binders regularly, and have your accountant set the authoritative retention schedule. Do not treat SR&ED Copilot as the sole archive.

9. Access, correction, export, and deletion

Subject to verification, applicable law, and account permissions, you may:

  • review and correct account or customer content using available product controls;
  • download available narratives, documents, project preparer review binders, and, for owners, a sanitized organization JSON export and data inventory;
  • disconnect integrations to stop future access;
  • when disconnecting, choose to keep imported evidence or permanently purge matching evidence and its citation links after reviewing impact counts;
  • delete individual records where the product provides a delete action;
  • ask the customer organization's account owner to handle a workforce privacy request; and
  • request an account-level access, export, correction, or deletion action through the privacy contact.

When an organization owner offboards a user, the Service revokes sessions and login credentials, clears MFA and recovery material, and replaces the user's sign-in identity with a non-login former-user placeholder. The underlying user record remains so narrative authorship, approvals, completed reviews, and audit relationships are not silently deleted or reassigned. Customers that need a different legal-retention or attribution outcome should make a verified privacy request.

Choosing “keep” during disconnect retains previously imported evidence; choosing “purge” permanently removes matching provider evidence and citation links from primary application data. Export and purge features do not necessarily include every service log, billing record, provider backup, or internal security record. We may retain limited information where legally required or necessary to protect the Service.

10. Business transfers

If a merger, financing, acquisition, reorganization, insolvency event, or asset sale may transfer control of customer information, we will target at least 30 days advance notice where legally and commercially practicable. Before the effective transfer, a customer may stop submitting new data, export available records, terminate future use, and request deletion. Deletion remains subject to legal preservation and backup rotation. Any successor must assume the applicable privacy and contractual obligations or establish another lawful basis before continuing covered processing.

11. Employer and workforce accountability

Customers remain accountable for employee and contractor information they send to the Service. Before connecting workplace systems, customers should complete their vendor and privacy review, identify an appropriate legal basis, give required notices, minimize collection, restrict access, and confirm cross-border and retention requirements. Employees should direct organization-controlled data requests to their employer first; we will reasonably assist the account owner.

12. Analytics and communication choices

Google Ads measurement runs only on designated public marketing and registration pages. Advertising, user-data, personalization, and analytics storage are denied by default. If you allow measurement, Google may use first-party advertising cookies and ad-click identifiers for campaign attribution. If you decline, those storage purposes remain denied and ad data is redacted; Google may still receive cookieless consent, public-page, and completed-sign-up signals for aggregate conversion measurement. Use the “Privacy choices” control on a public page to change your selection.

Google Ads is not loaded on authenticated dashboard, welcome, invitation, or password-reset routes, and no claim, evidence, project, expenditure, narrative, account-email, or form-field content is sent in the sign-up conversion event. You may unsubscribe from optional marketing messages using the message instructions. We may still send account, billing, security, legal, and service messages needed to operate the relationship. See the Subprocessor Register for active service providers.

Authenticated product and educational-resource routes may record a small set of first-party interaction events in SR&ED Copilot hosting logs. Those events contain a controlled event name and interface source only; the product analytics client does not include user, organization, project, amount, or free-text form fields, and these events are not forwarded to Google Ads.

13. Children

The Service is for businesses and is not intended for anyone under 18. Do not submit children's personal information as SR&ED evidence.

14. Changes

We may update this policy as the Service changes. We will post the new effective date and provide advance email notice of material changes where reasonably practicable or contractually required. The current policy remains available on this page.

15. Contact

Privacy requests: privacy@sredcopilot.ca
Security and legal questions: hello@sredcopilot.ca
Operator: Andrew Marc, carrying on business as SR&ED Copilot, based in Halifax, Nova Scotia, Canada